Threat Level: green Handler on Duty: Scott Fendley

SANS ISC InfoSec Handlers Diary Blog


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

MS06-041: Vulnerability in DNS Resolution Could Allow Remote Code Execution (920683)

Published: 2006-08-08
Last Updated: 2006-08-08 18:51:12 UTC
by Marcus Sachs (Version: 1)
0 comment(s)
MS06-041 - KB 920683 - CVE-2006-3440 - CVE-2006-3441

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Recommendation: Apply the update immediately

Affected Software:

Windows 2000 SP4
Windows XP SP1 and SP2
Windows XP for x64
Windows Server 2003 (including SP1)
Windows Server 2003 for Itanium (including SP1)
Windows Server 2003 for x64

There are two vulnerabilities covered in this bulletin:

Winsock Hostname Vulnerability - CVE-2006-3440:

There is a remote code execution vulnerability in Winsock that could allow an attacker who successfully exploited this vulnerability to take complete control of the affected system. For an attack to be successful the attacker would have to force the user to open a file or visit a website that is specially crafted to call the affected Winsock API.

DNS Client Buffer Overrun Vulnerability - CVE-2006-3441:

There is a remote code execution vulnerability in the DNS Client service that could allow an attacker who successfully exploited this vulnerability to take complete control of the affected system.


Marcus H. Sachs
SRI International

Keywords:
0 comment(s)
Diary Archives